4.3
CVE-2012-1956
- EPSS 0.74%
- Published 29.08.2012 10:56:39
- Last modified 11.04.2025 00:51:21
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 do not prevent use of the Object.defineProperty method to shadow the location object (aka window.location), which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via vectors involving a plugin.
Data is provided by the National Vulnerability Database (NVD)
Mozilla ≫ Thunderbird Version <= 14.0
Mozilla ≫ Thunderbird Version1.0
Mozilla ≫ Thunderbird Version1.0.1
Mozilla ≫ Thunderbird Version1.0.2
Mozilla ≫ Thunderbird Version1.0.3
Mozilla ≫ Thunderbird Version1.0.4
Mozilla ≫ Thunderbird Version1.0.5
Mozilla ≫ Thunderbird Version1.0.5 Updatebeta
Mozilla ≫ Thunderbird Version1.0.6
Mozilla ≫ Thunderbird Version1.0.7
Mozilla ≫ Thunderbird Version1.0.8
Mozilla ≫ Thunderbird Version1.5
Mozilla ≫ Thunderbird Version1.5 Updatebeta2
Mozilla ≫ Thunderbird Version1.5.0.1
Mozilla ≫ Thunderbird Version1.5.0.2
Mozilla ≫ Thunderbird Version1.5.0.3
Mozilla ≫ Thunderbird Version1.5.0.4
Mozilla ≫ Thunderbird Version1.5.0.5
Mozilla ≫ Thunderbird Version1.5.0.6
Mozilla ≫ Thunderbird Version1.5.0.7
Mozilla ≫ Thunderbird Version1.5.0.8
Mozilla ≫ Thunderbird Version1.5.0.9
Mozilla ≫ Thunderbird Version1.5.0.10
Mozilla ≫ Thunderbird Version1.5.0.11
Mozilla ≫ Thunderbird Version1.5.0.12
Mozilla ≫ Thunderbird Version1.5.0.13
Mozilla ≫ Thunderbird Version1.5.0.14
Mozilla ≫ Thunderbird Version1.5.1
Mozilla ≫ Thunderbird Version1.5.2
Mozilla ≫ Thunderbird Version1.7.1
Mozilla ≫ Thunderbird Version1.7.3
Mozilla ≫ Thunderbird Version2.0
Mozilla ≫ Thunderbird Version2.0.0.0
Mozilla ≫ Thunderbird Version2.0.0.1
Mozilla ≫ Thunderbird Version2.0.0.2
Mozilla ≫ Thunderbird Version2.0.0.3
Mozilla ≫ Thunderbird Version2.0.0.4
Mozilla ≫ Thunderbird Version2.0.0.5
Mozilla ≫ Thunderbird Version2.0.0.6
Mozilla ≫ Thunderbird Version2.0.0.7
Mozilla ≫ Thunderbird Version2.0.0.8
Mozilla ≫ Thunderbird Version2.0.0.9
Mozilla ≫ Thunderbird Version2.0.0.11
Mozilla ≫ Thunderbird Version2.0.0.12
Mozilla ≫ Thunderbird Version2.0.0.13
Mozilla ≫ Thunderbird Version2.0.0.14
Mozilla ≫ Thunderbird Version2.0.0.15
Mozilla ≫ Thunderbird Version2.0.0.16
Mozilla ≫ Thunderbird Version2.0.0.17
Mozilla ≫ Thunderbird Version2.0.0.18
Mozilla ≫ Thunderbird Version2.0.0.19
Mozilla ≫ Thunderbird Version2.0.0.20
Mozilla ≫ Thunderbird Version2.0.0.21
Mozilla ≫ Thunderbird Version2.0.0.22
Mozilla ≫ Thunderbird Version2.0.0.23
Mozilla ≫ Thunderbird Version3.0
Mozilla ≫ Thunderbird Version3.0.1
Mozilla ≫ Thunderbird Version3.0.2
Mozilla ≫ Thunderbird Version3.0.3
Mozilla ≫ Thunderbird Version3.0.4
Mozilla ≫ Thunderbird Version3.0.5
Mozilla ≫ Thunderbird Version3.0.6
Mozilla ≫ Thunderbird Version3.0.7
Mozilla ≫ Thunderbird Version3.0.8
Mozilla ≫ Thunderbird Version3.0.9
Mozilla ≫ Thunderbird Version3.0.10
Mozilla ≫ Thunderbird Version3.0.11
Mozilla ≫ Thunderbird Version3.1
Mozilla ≫ Thunderbird Version3.1.1
Mozilla ≫ Thunderbird Version3.1.2
Mozilla ≫ Thunderbird Version3.1.3
Mozilla ≫ Thunderbird Version3.1.4
Mozilla ≫ Thunderbird Version3.1.5
Mozilla ≫ Thunderbird Version3.1.6
Mozilla ≫ Thunderbird Version3.1.7
Mozilla ≫ Thunderbird Version3.1.8
Mozilla ≫ Thunderbird Version3.1.9
Mozilla ≫ Thunderbird Version3.1.10
Mozilla ≫ Thunderbird Version3.1.11
Mozilla ≫ Thunderbird Version3.1.12
Mozilla ≫ Thunderbird Version3.1.13
Mozilla ≫ Thunderbird Version3.1.14
Mozilla ≫ Thunderbird Version3.1.15
Mozilla ≫ Thunderbird Version3.1.16
Mozilla ≫ Thunderbird Version3.1.17
Mozilla ≫ Thunderbird Version5.0
Mozilla ≫ Thunderbird Version6.0
Mozilla ≫ Thunderbird Version6.0.1
Mozilla ≫ Thunderbird Version6.0.2
Mozilla ≫ Thunderbird Version7.0
Mozilla ≫ Thunderbird Version7.0.1
Mozilla ≫ Thunderbird Version8.0
Mozilla ≫ Thunderbird Version9.0
Mozilla ≫ Thunderbird Version9.0.1
Mozilla ≫ Thunderbird Version10.0
Mozilla ≫ Thunderbird Version10.0.1
Mozilla ≫ Thunderbird Version10.0.2
Mozilla ≫ Thunderbird Version10.0.3
Mozilla ≫ Thunderbird Version10.0.4
Mozilla ≫ Thunderbird Version11.0
Mozilla ≫ Thunderbird Version12.0
Mozilla ≫ Thunderbird Version13.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.74% | 0.706 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.